Catalina - Enable Firewall Logging

Information

Firewall logging _MUST_ be enabled.

Firewall logging ensures that malicious network activity will be logged to the system.

NOTE: The firewall data is logged to Apple's Unified Logging with the subsystem com.apple.alf and the data is marked as private.

Solution

[source,bash]
----
/usr/libexec/ApplicationFirewall/socketfilterfw --setloggingmode on
----

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AU-12, 800-53|CM-6b., 800-53|SC-7, CCE|CCE-84757-4, CCI|CCI-000366

Plugin: Unix

Control ID: c12dd01e2dd50af920a73dc70be2efefcaa978ca90bead7f1caf2bc24f38bafe